WordPress Newsletters 插件在所有 4.17 及更早版本中存在授权绕过漏洞。该漏洞是由于插件未正确验证用户是否有权执行特定操作所致。因此,具备作者级(author)及以上权限的已认证攻击者,可以在正常帖子提交过程中伪造 POST 字段,从而向任何 WordPress 角色(包括管理员)的用户发送任意新闻邮件。攻击者可通过 POST 字段传入角色 slug,并将其直接传递给 函数,导致未经授权的大规模邮件发送,并可能利用网站自身的出站邮件通道对特权用户进行钓鱼攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| contrid | Newsletters | ≤ 4.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| contrid | Newsletters | 0 ~ 4.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet